Forum Discussion
tiwang
Nimbostratus
Jun 07, 2013SSO for webserver
Hi out there
I need an idea how I can awoid my users in cheating me.
I have a SSO setup where I through a client initiated webform do a SSO login to a webserver. After this the APM j...
Kevin_Stewart
Employee
Jun 11, 2013This is a tough one. An APM session is generally maintained by a session-based browser cookie, and it is the browser's behavior to share that memory space across windows/tabs that allows a second window to proceed past the initial access policy evaluation. I have two initial thoughts:
1. Is the application's logon page something distinct (ex. /logon.aspx) that no one would need to access unless attempting to logon?
2. The SSO profile should be perpetual. It should detect any request, at any time, to the logon page and submit the credentials so that the user never sees it. Can you elaborate on how logon is performed and how the SSO is configured?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
